Sonorie Studio

Privacy Policy

Last updated 1 August 2026

This explains what Sonorie collects, why, who else processes it, and how to get it back or deleted. It describes what the software actually does, not what a template says it might.

The short version

  • No advertising, no session replay, and nothing sold to data brokers. We measure traffic two ways: a cookie-free Cloudflare counter that identifies nobody, and Google Analytics — which runs only if you say yes, and never before.
  • We never sell or share your personal information, and we don’t train models on your content.
  • Your prompts go to inference providers so they can be processed. That is the main way your data leaves us — see who processes your data.
  • We never see your card details. Stripe handles payments on its own pages.

Who we are

Sonorie is a service for building audio plugins by describing them. For data protection purposes we are the controller of the personal data described here. The operator is MIMOSA SOLUTIONS LLC.

Privacy questions and requests: [email protected].

What we collect

Account information

Your email address, an optional display name, and — if you sign up with a password — a bcrypt hash of it. We never store the password itself. If you sign in with Google we receive and store your Google account identifier, email address, whether Google has verified it, and your name; we do not receive your Google password and we ask for no other Google data. If you enable two-factor authentication we store the secret needed to verify your codes and hashes of your backup codes.

What you create

Your prompts and chat history, any images you attach, the plugins generated for you (DSP source, interface code, parameters), your project titles, and the version history of each project. If you publish to the marketplace, your listing text and the plugin snapshot behind it. If you write a review, its rating and text, shown publicly with your name.

Billing and usage

Your plan, subscription status, and the Stripe customer and subscription identifiers that link you to your payments. Purchases, top-ups and licences issued to you. Usage records for each generation: which route it took, whether it succeeded, how long it took, how many tokens it used and what it cost. Card numbers never reach us— payment details are entered on Stripe’s own pages.

Sign-in sessions

For each active session we store a hash of the session token, when it expires, and the browser user-agent string captured when you signed in. The last of those exists for one reason: so the security page can show you a recognisable list of your signed-in devices and you can end any you don’t recognise.

IP addresses

Your IP address is used transiently, in memory, to rate-limit sign-in and account actions so nobody can brute-force your account. We do not write IP addresses to our database. Cloudflare, which delivers and protects the site, necessarily sees the IP of every request as part of doing that, and processes it under its own terms.

What we do not collect

No advertising or analytics identifiers, no cross-site tracking, no behavioural profiling, no location beyond the coarse country your network implies, and no special-category data. We do not buy data about you from anyone.

Why we use it, and our legal basis

For anyone in the UK, EU or Switzerland, the GDPR requires us to name a lawful basis for each purpose:

PurposeDataLegal basis
Running your account and generating pluginsAccount details, prompts, projects, generated codePerformance of our contract with you
Taking payment, managing subscriptions and marketplace payoutsBilling identifiers, purchases, usage totalsPerformance of a contract; legal obligation for tax records
Service emails — verification, password resets, receipts, security alertsEmail address, the relevant eventPerformance of a contract; legitimate interest in account security
Keeping accounts secure and preventing abuseIP address (transiently), user-agent, rate-limit countersLegitimate interest in protecting users and the service
Improving reliability and cost of the pipelineAggregate timings, costs, pass ratesLegitimate interest in operating a working service
Meeting legal and accounting obligationsInvoices and transaction recordsLegal obligation

Where we rely on legitimate interests, we have considered your rights and use the least data that achieves the purpose — which is why, for example, rate limiting keeps IP addresses in memory instead of logging them.

Who processes your data

We use a small number of providers to run the service. Each acts on our instructions under a data-processing agreement, and each receives only what its job needs.

ProviderWhat it doesWhat it receives
Inference providersRun the compute behind plugin generationYour prompt text, attached images, conversation context, generated code
StripePayments, subscriptions, marketplace payoutsEmail, name, an internal user id, and your payment details, which you give directly to Stripe
ResendSends transactional emailYour email address and the content of that message
GoogleSign in with Google — only if you use itThe sign-in exchange itself; Google returns your identifier, email and name
CloudflareDelivers and protects the site; stores compiled build artifactsRequest metadata including your IP address; plugin binaries, which hold no personal data
Our database and server hostingStores everything described aboveAll account, project and billing data
Our compile and build workersCompile generated C++ into a preview or a plugin binaryThe generated source code only

A word about prompts. The content you type is sent to third-party inference providers so it can be processed, and they handle it under their own terms and retention policies. Which providers we use changes over time; they are currently located in the United States and China. We don’t list them by name here because that list would be out of date within months, but it isn’t a secret — ask us and we will tell you which providers are handling your data. Please don’t put personal, confidential or client-sensitive information into a prompt. You don’t need to in order to describe a compressor, and it is the one part of this policy where your own habits matter more than our controls.

Beyond these providers, we disclose personal data only where the law requires it, to establish or defend legal claims, or — with notice to you where we’re allowed to give it — if the business is ever transferred to another owner. We do not sell personal information and we do not share it for advertising.

International transfers

Our providers operate outside the UK, EEA and Switzerland, including in the United States and China. Where personal data is transferred out of those regions we rely on the European Commission’s Standard Contractual Clauses and the UK Addendum, together with the provider’s own safeguards. Not every destination has been found by the Commission to offer an equivalent level of protection — which is the practical reason for the caution about prompt content above.

How long we keep it

DataKept for
Account detailsWhile your account exists, then deleted on closure
Projects, chat history, generated codeUntil you delete them, or until the account is closed
Sign-in sessions30 days, or until you sign out or revoke the device
Generation job records14 days, then swept automatically
Usage and cost recordsUp to 24 months, for billing accuracy and capacity planning
Invoices, purchases and payoutsAs long as tax and accounting law requires, typically 6–10 years
Marketplace licencesFor the life of the licence, so buyers can re-activate a plugin they bought

How we protect it

Passwords are hashed with bcrypt and never stored in the clear. Session tokens are stored only as hashes, so a copy of our database does not yield working sessions. Traffic is HTTPS-only with HSTS. Sign-in and account actions are rate-limited, and password checks take the same time whether or not the account exists, so they can’t be used to discover who has an account. Model-generated code is compiled in an isolated, hardened service and runs in the browser inside a sandboxed frame that cannot reach the network. Two-factor authentication is available and we recommend it.

No system is perfectly secure. If we ever suffer a breach affecting your personal data, we will notify you and the relevant regulator as the law requires.

Your rights

Depending on where you live you may have the right to access your data, correct it, delete it, receive a portable copy, restrict or object to certain processing, and withdraw consent where we relied on it. If you are in California or a similar US state, you have the right to know, delete and correct, and the right to opt out of sale or sharing — which we can satisfy immediately, because we do neither. We will not discriminate against you for exercising any of these rights.

Some of it you can do yourself, right now:

  • Change your name, email or password on the account page.
  • Review and revoke signed-in devices on the security page.
  • Delete individual projects from the studio.
  • Manage or cancel your subscription through the billing portal.

For account deletion or a copy of your data, email [email protected] from your account address and we will action it within 30 days. Deleting your account removes your projects, chat history, generated code, sessions and usage records; we keep billing records where tax law requires it, and marketplace purchase and licence records so that people who bought from you keep working plugins.

If you think we have handled your data badly, please tell us first — but you also have the right to complain to your data protection authority. In the EU that is the supervisory authority where you live or work; in the UK, the Information Commissioner’s Office; in Switzerland, the Federal Data Protection and Information Commissioner.

Cookies and local storage

Sonorie sets three strictly necessary cookies to sign you in and keep the sign-in flow safe. Those always run: blocking them would simply stop you being able to sign in, so there is no choice to offer about them.

CookiePurposeExpires
sonore_sessionKeeps you signed in. Holds a random token; the server stores only its hash.30 days
sonore_2faBridges the gap between your password and your two-factor code.10 minutes
sonore_oauthProtects the Google sign-in exchange against forgery and interception.10 minutes

All three are HttpOnly, restricted to our own site with SameSite=Lax, and sent only over HTTPS in production. That means no script — ours or anyone else’s — can read them.

Analytics

We measure how the site is used in two ways, and they are treated differently because they are different things.

Cloudflare Web Analyticsruns for everyone. It sets no cookie and stores nothing on your device — it counts page views without building any profile of who you are, so there is nothing to consent to and nothing you could usefully refuse. It is the reason our traffic figures are honest rather than being “whatever the people who accepted happened to do”.

Google Analytics (loaded via Google Tag Manager) runs only if you accept it. Refuse, or ignore the banner, and the script is never loaded at all — not loaded-then-muted, not loaded in a restricted mode. It is not there. Accepting sets these cookies:

CookiePurposeExpires
_gaGoogle Analytics: tells returning visits apart from new ones.2 years
_ga_<id>Google Analytics: keeps the current session together.2 years

Google LLC processes this data as our processor, which means it leaves the EU and is handled in the United States under the EU–US Data Privacy Framework and Standard Contractual Clauses. We switch on IP anonymisation, we do not run Google Signals, advertising features or cross-device tracking, and we do not use this data to build advertising audiences.

You can change your mind at any time, and it takes effect straight away — refusing after having accepted also deletes the _ga cookies from your browser rather than merely stopping new ones.

You haven’t answered yet, so Google Analytics is not running.

We also keep a few things in your browser’s local storage. The preferences never leave your device. The last two do: they are read once, when you create an account, and then they stop mattering.

KeyWhat it remembers
sonorie-themeLight or dark, if you chose one explicitly
sonore-storeStudio preferences such as output level
sonore-cartWhat’s in your marketplace cart
sonore-pending-promptA prompt you typed before signing up, so it survives the redirect. Expires after 24 hours.
sonorie-cookie-noticeThat you dismissed the cookie notice, so we don’t show it again
sonore-refWhich member’s invite link brought you, so they get credit if you sign up. Sent to us once, at signup. Expires after 90 days.
sonore-attrWhich advert brought you — for example a campaign name from the link, or a Google or Meta click id. We use it to tell which of our own adverts are worth paying for. It is a first-party record: no advertising network can read it, we set no advertising cookie, and it is sent to us once, at signup. Expires after 30 days.

You can clear all of it at any time through your browser’s settings. Clearing it signs you out and resets your preferences; nothing else is lost.

Children

Sonorie is not for people under 18. We don’t knowingly collect their personal data, and if we learn we have, we delete it. If you believe a child has given us information, please email [email protected].

Changes to this policy

If we change what we collect or who processes it, we will update this page and change the date at the top. For material changes we will tell you by email or in the app before they take effect. If we ever add a service that is not strictly necessary — analytics, for example — we will ask for your consent first rather than assume it.

Contact

[email protected] for anything in this policy, or [email protected] for everything else.

MIMOSA SOLUTIONS LLC

See also our Terms of Service.

Sonorie
MercadoBlogTérminosPrivacidadReportar contenidoContactoDiscord
© 2026 Sonorie · MIMOSA SOLUTIONS LLC

Sonorie necesita unas pocas cookies para iniciar tu sesión — esas siempre funcionan. También nos gustaría usar Google Analytics para ver cómo se usa el sitio. Eso lo decides tú, y decir no no cambia nada en el funcionamiento de Sonorie. Qué guardamos